CVE-2023-29000 to CVE-2023-29999
137 CVEs with public proof-of-concept exploits.
- CVE-2023-290031 PoCSvelteKit has Insufficient Cross-Site Request Forgery Protection
- CVE-2023-290041 PoCPath Traversal Vulnerability in hap-wi/roxy-wi
- CVE-2023-290072 PoCsArbitrary configuration injection via `git submodule deinit`
- CVE-2023-290081 PoCSvelteKit framework has Insufficient CSRF protection for CORS requests
- CVE-2023-290175 PoCsvm2 Sandbox Escape vulnerability
- CVE-2023-290843 PoCsZoho ManageEngine ADManager Plus before 7181 allows for authenticated users to exploit command injection via Proxy settings.
- CVE-2023-291592 PoCsDirectory traversal vulnerability in Starlette versions 0.13.5 and later and prior to 0.27.0 allows a remote unauthenticated attacker to…
- CVE-2023-291992 PoCsvm2 Sandbox escape vulnerability
- CVE-2023-292011 PoCorg.xwiki.commons:xwiki-commons-xml Cross-site Scripting vulnerability
- CVE-2023-292041 PoCURL Redirection to Untrusted Site ('Open Redirect') in org.xwiki.platform:xwiki-platform-oldcore
- CVE-2023-292051 PoCorg.xwiki.platform:xwiki-platform-rendering-xwiki vulnerable to stored cross-site scripting via HTML and raw macro
- CVE-2023-292091 PoCorg.xwiki.platform:xwiki-platform-legacy-notification-activitymacro Eval Injection vulnerability
- CVE-2023-292101 PoCorg.xwiki.platform:xwiki-platform-notifications-ui Eval Injection vulnerability
- CVE-2023-292111 PoCorg.xwiki.platform:xwiki-platform-wiki-ui-mainwiki Eval Injection vulnerability
- CVE-2023-292121 PoCxwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
- CVE-2023-292141 PoCorg.xwiki.platform:xwiki-platform-panels-ui Eval Injection vulnerability
- CVE-2023-292982 PoCsKEVAdobe ColdFusion Improper Access Control Security feature bypass
- CVE-2023-293003 PoCsKEVAdobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
- CVE-2023-293252 PoCsWindows OLE Remote Code Execution Vulnerability
- CVE-2023-293363 PoCsKEVWin32k Elevation of Privilege Vulnerability
- CVE-2023-293432 PoCsSysInternals Sysmon for Windows Elevation of Privilege Vulnerability
- CVE-2023-293579 PoCsKEVMicrosoft SharePoint Server Elevation of Privilege Vulnerability
- CVE-2023-293602 PoCsKEVMicrosoft Streaming Service Elevation of Privilege Vulnerability
- CVE-2023-293831 PoCIn Shadow 4.13, it is possible to inject control characters into fields provided to the SUID program chfn (change finger). Although it is…
- CVE-2023-293841 PoCWordPress WordPress Job Board and Recruitment Plugin – JobWP Plugin <= 2.0 is vulnerable to Arbitrary File Upload
- CVE-2023-293861 PoCWordPress Manager for Icomoon plugin <= 2.0 - Arbitrary File Upload vulnerability
- CVE-2023-294011 PoCImproper handling of filenames in Content-Disposition HTTP header in github.com/gin-gonic/gin
- CVE-2023-294091 PoCLarge RSA keys can cause high CPU usage in crypto/tls
- CVE-2023-294393 PoCsWordPress FooGallery Plugin <= 2.2.35 is vulnerable to Cross Site Scripting (XSS)
- CVE-2023-294651 PoCSageMath FlintQS 1.0 relies on pathnames under TMPDIR (typically world-writable), which (for example) allows a local user to overwrite…
- CVE-2023-294781 PoCBiblioCraft before 2.4.6 does not sanitize path-traversal characters in filenames, allowing restricted write access to almost anywhere on…
- CVE-2023-294831 PoCeventlet before 0.35.2, as used in dnspython before 2.6.0, allows remote attackers to interfere with DNS name resolution by quickly…
- CVE-2023-2948919 PoCsAn issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669.…
- CVE-2023-294911 PoCncurses before 6.4 20230408, when used by a setuid application, allows local users to trigger security-relevant memory corruption via…
- CVE-2023-295062 PoCsorg.xwiki.platform:xwiki-platform-security-authentication-default XSS with authenticated endpoints
- CVE-2023-295101 PoCCode injection via unescaped translations in xwiki-platform
- CVE-2023-295171 PoCExposure of Sensitive Information to an Unauthorized Actor in org.xwiki.platform:xwiki-platform-office-viewer
- CVE-2023-295191 PoCCode injection in org.xwiki.platform:xwiki-platform-attachment-ui
- CVE-2023-295231 PoCCode injection in display method used in user profiles in xwiki-platform
- CVE-2023-295282 PoCsCross-site Scripting in org.xwiki.commons:xwiki-commons-xml
- CVE-2023-295621 PoCTP-Link TL-WPA7510 (EU)_V2_190125 was discovered to contain a stack overflow via the operation parameter at /admin/locale.
- CVE-2023-295661 PoChuedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability…
- CVE-2023-295691 PoCCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via ffi_cb_impl_wpwwwww at src/mjs_ffi.c. This vulnerability can lead…
- CVE-2023-295702 PoCsCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via mjs_ffi_cb_free at src/mjs_ffi.c. This vulnerability can lead to a…
- CVE-2023-295712 PoCsCesanta MJS v2.20.0 was discovered to contain a SEGV vulnerability via gc_sweep at src/mjs_gc.c. This vulnerability can lead to a Denial…
- CVE-2023-295732 PoCsBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp4info component.
- CVE-2023-295742 PoCsBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42avc component.
- CVE-2023-295752 PoCsBento4 v1.6.0-639 was discovered to contain an out-of-memory bug in the mp42aac component.
- CVE-2023-295762 PoCsBento4 v1.6.0-639 was discovered to contain a segmentation violation via the AP4_TrunAtom::SetDataOffset(int) function in Ap4TrunAtom.h.
- CVE-2023-295781 PoCmp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the mp4v2::impl::MP4StringProperty::~MP4StringProperty() function at…
- CVE-2023-295791 PoCyasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the component yasm/yasm+0x43b466 in vsprintf. Note: This has been…
- CVE-2023-295802 PoCsyasm 1.3.0.55.g101bc was discovered to contain a segmentation violation via the component yasm_expr_create at /libyasm/expr.c.
- CVE-2023-295812 PoCsyasm 1.3.0.55.g101bc has a segmentation violation in the function delete_Token at modules/preprocs/nasm/nasm-pp.c. NOTE: although a…
- CVE-2023-295821 PoCyasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr1 at /nasm/nasm-parse.c. Note: This has been…
- CVE-2023-295831 PoCyasm 1.3.0.55.g101bc was discovered to contain a stack overflow via the function parse_expr5 at /nasm/nasm-parse.c. Note: This has been…
- CVE-2023-295842 PoCsmp4v2 v2.0.0 was discovered to contain a heap buffer overflow via the MP4GetVideoProfileLevel function at /src/mp4.cpp.
- CVE-2023-296221 PoCPurchase Order Management v1.0 was discovered to contain a SQL injection vulnerability via the password parameter at…
- CVE-2023-296231 PoCPurchase Order Management v1.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the password parameter…
- CVE-2023-296291 PoCPrestaShop jmsthemelayout 2.5.5 is vulnerable to SQL Injection via ajax_jmsvermegamenu.php.
- CVE-2023-296301 PoCPrestaShop jmsmegamenu 1.1.x and 2.0.x is vulnerable to SQL Injection via ajax_jmsmegamenu.php.
- CVE-2023-296321 PoCPrestaShop jmspagebuilder 3.x is vulnerable to SQL Injection via ajax_jmspagebuilder.php.
- CVE-2023-296561 PoCAn improper authorization vulnerability in Darktrace mobile app (Android) prior to version 6.0.15 allows disabled and low-privilege users…
- CVE-2023-296591 PoCA Segmentation fault caused by a floating point exception exists in libheif 1.15.1 using crafted heif images via the…
- CVE-2023-296651 PoCD-Link DIR823G_V1.0.2B05 was discovered to contain a stack overflow via the NewPassword parameters in SetPasswdSettings.
- CVE-2023-296891 PoCPyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template injection (SSTI)…
- CVE-2023-296931 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function set_tftp_upgrad.
- CVE-2023-296961 PoCH3C GR-1200W MiniGRW1A0V100R006 was discovered to contain a stack overflow via the function version_set.
- CVE-2023-297121 PoCCross Site Scripting vulnerability found in Vade Secure Gateway allows a remote attacker to execute arbitrary code via a crafted payload…
- CVE-2023-297221 PoCThe Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized apps to actively request permission to modify data in the…
- CVE-2023-297231 PoCThe Glitter Unicorn Wallpaper app for Android 7.0 thru 8.0 allows unauthorized applications to actively request permission to insert data…
- CVE-2023-297241 PoCThe BT21 x BTS Wallpaper app 12 for Android allows unauthorized apps to actively request permission to modify data in the database that…
- CVE-2023-297251 PoCThe BT21 x BTS Wallpaper app 12 for Android allows unauthorized applications to actively request permission to insert data into the…
- CVE-2023-297261 PoCThe Call Blocker application 6.6.3 for Android incorrectly opens a key component that an attacker can use to inject large amounts of dirty…
- CVE-2023-297271 PoCThe Call Blocker application 6.6.3 for Android allows unauthorized applications to use exposed components to delete data stored in its…
- CVE-2023-297281 PoCThe Call Blocker application 6.6.3 for Android allows attackers to tamper with feature-related data, resulting in a severe elevation of…
- CVE-2023-297311 PoCSoLive 1.6.14 thru 1.6.20 for Android has an exposed component that provides a method to modify the SharedPreference file. An attacker can…
- CVE-2023-297321 PoCSoLive 1.6.14 thru 1.6.20 for Android exists exposed component, the component provides the method to modify the SharedPreference file. The…
- CVE-2023-297331 PoCThe Lock Master app 2.2.4 for Android allows unauthorized apps to modify the values in its SharedPreference files. These files hold data…
- CVE-2023-297341 PoCAn issue found in edjing Mix v.7.09.01 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the…
- CVE-2023-297351 PoCAn issue found in edjing Mix v.7.09.01 for Android allows a local attacker to cause a denial of service via the database files.
- CVE-2023-297361 PoCKeyboard Themes 1.275.1.164 for Android contains a dictionary traversal vulnerability that allows unauthorized apps to overwrite arbitrary…
- CVE-2023-297371 PoCAn issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause a denial of service via the database…
- CVE-2023-297381 PoCAn issue found in Wave Animated Keyboard Emoji v.1.70.7 for Android allows a local attacker to cause code execution and escalation of…
- CVE-2023-297391 PoCAn issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause escalation of privilege attacks by…
- CVE-2023-297401 PoCAn issue found in Alarm Clock for Heavy Sleepers v.5.3.2 for Android allows unauthorized apps to cause a denial of service attack by…
- CVE-2023-297411 PoCAn issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause an escalation of privileges attack by manipulating the…
- CVE-2023-297421 PoCAn issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a code execution attack by manipulating the database.
- CVE-2023-297431 PoCAn issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating…
- CVE-2023-297451 PoCAn issue found in BestWeather v.7.3.1 for Android allows unauthorized apps to cause a persistent denial of service attack by manipulating…
- CVE-2023-297461 PoCAn issue found in The Thaiger v.1.2 for Android allows unauthorized apps to cause a code execution attack by manipulating the…
- CVE-2023-297471 PoCStory Saver for Instragram - Video Downloader 1.0.6 for Android exists exposed component, the component provides the method to modify the…
- CVE-2023-297481 PoCStory Saver for Instragram - Video Downloader 1.0.6 for Android has an exposed component that provides a method to modify the…
- CVE-2023-297491 PoCAn issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating…
- CVE-2023-297511 PoCAn issue found in Yandex Navigator v.6.60 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the…
- CVE-2023-297521 PoCAn issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows unauthorized apps to cause escalation of privilege attacks by…
- CVE-2023-297531 PoCAn issue found in Facemoji Emoji Keyboard v.2.9.1.2 for Android allows a local attacker to cause a denial of service via the…
- CVE-2023-297551 PoCAn issue found in Twilight v.13.3 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating the…
- CVE-2023-297561 PoCAn issue found in Twilight v.13.3 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the…
- CVE-2023-297571 PoCAn issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause escalation of privilege attacks by manipulating…
- CVE-2023-297581 PoCAn issue found in Blue Light Filter v.1.5.5 for Android allows unauthorized apps to cause a persistent denial of service by manipulating…
- CVE-2023-297591 PoCAn issue found in FlightAware v.5.8.0 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the…
- CVE-2023-297611 PoCAn issue found in Sleep v.20230303 for Android allows unauthorized apps to cause a persistent denial of service by manipulating the…
- CVE-2023-297661 PoCAn issue found in CrossX v.1.15.3 for Android allows a local attacker to cause an escalation of Privileges via the database files.
- CVE-2023-297671 PoCAn issue found in CrossX v.1.15.3 for Android allows a local attacker to cause a persistent denial of service via the database files.
- CVE-2023-297701 PoCIn Sentrifugo 3.5, the AssetsController::uploadsaveAction function allows an authenticated attacker to upload any file without extension…
- CVE-2023-297981 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the command parameter in the…
- CVE-2023-297991 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the hostname parameter in the…
- CVE-2023-298001 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the FileName parameter in the…
- CVE-2023-298011 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain multiple command injection vulnerabilities via the rtLogEnabled and…
- CVE-2023-298021 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the ip parameter in the…
- CVE-2023-298031 PoCTOTOLINK X18 V9.1.0cu.2024_B20220329 was discovered to contain a command injection vulnerability via the pid parameter in the…
- CVE-2023-298041 PoCWFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the sys_smb_pwdmod function.
- CVE-2023-298051 PoCWFS-SR03 v1.0.3 was discovered to contain a command injection vulnerability via the pro_stor_canceltrans_handler_part_19 function.
- CVE-2023-298082 PoCsCross Site Scripting (XSS) vulnerability in vogtmh cmaps (companymaps) 8.0 allows attackers to execute arbitrary code.
- CVE-2023-298093 PoCsSQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbitrary code via a…
- CVE-2023-298241 PoCA use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the vendor and discoverer…
- CVE-2023-298274 PoCsejs v3.1.9 is vulnerable to server-side template injection. If the ejs file is controllable, template injection can be implemented through…
- CVE-2023-298391 PoCA Stored Cross Site Scripting (XSS) vulnerability exists in multiple pages of Hotel Druid version 3.0.4, which allows arbitrary execution…
- CVE-2023-298422 PoCsChurchCRM 4.5.4 endpoint /EditEventTypes.php is vulnerable to Blind SQL Injection (Time-based) via the EN_tyid POST parameter.
- CVE-2023-298471 PoCAeroCMS v0.0.1 was discovered to contain multiple stored cross-site scripting (XSS) vulnerabilities via the comment_author and…
- CVE-2023-298482 PoCsBang Resto 1.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the itemName parameter in the…
- CVE-2023-298492 PoCsBang Resto 1.0 was discovered to contain multiple SQL injection vulnerabilities via the btnMenuItemID, itemID, itemPrice, menuID, staffID,…
- CVE-2023-298501 PoCSENAYAN Library Management System (SLiMS) Bulian v9.5.2 does not strip exif data from uploaded images. This allows attackers to obtain…
- CVE-2023-298611 PoCAn issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the…
- CVE-2023-298621 PoCAn issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and…
- CVE-2023-298871 PoCA Local File inclusion vulnerability in test.php in spreadsheet-reader 0.5.11 allows remote attackers to include arbitrary files via the…
- CVE-2023-299182 PoCsRosarioSIS 10.8.4 is vulnerable to CSV injection via the Periods Module.
- CVE-2023-299193 PoCsSolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is…
- CVE-2023-299223 PoCsPowerJob V4.3.1 is vulnerable to Incorrect Access Control via the create user/save interface.
- CVE-2023-299234 PoCsPowerJob V4.3.1 is vulnerable to Insecure Permissions. via the list job interface.
- CVE-2023-299301 PoCAn issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code…
- CVE-2023-299311 PoClaravel-s 3.7.35 is vulnerable to Local File Inclusion via /src/Illuminate/Laravel.php.
- CVE-2023-299501 PoCswfrender v0.9.2 was discovered to contain a heap buffer overflow in the function enumerateUsedIDs_fillstyle at modules/swftools.c
- CVE-2023-299631 PoCS-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
- CVE-2023-299731 PoCPfsense CE version 2.6.0 is vulnerable to No rate limit which can lead to an attacker creating multiple malicious users in firewall.
- CVE-2023-299833 PoCsCross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the…
- CVE-2023-299981 PoCA Cross-site scripting (XSS) vulnerability in the content editor in Gis3W g3w-suite 3.5 allows remote authenticated users to inject…